Enzoic for Active Directory
v3.6
v3.6
  • Overview
  • Installation & Setup
    • Installation Prerequisites
    • Setup Instructions
    • Client Setup Instructions
    • Upgrade Instructions
    • Automated Deployments
  • Product Usage
    • Enzoic Installed Product Console
      • Dashboard
      • System Health
      • Monitoring Policies
      • Settings
      • Reporting
        • Password Change Report
        • Continuous Monitoring Report
        • Monitored Users Report
        • Compromised Users Report
        • Users Sharing Passwords
        • Users with Passwords Set to Never Expire
        • Users with No Password Set
        • Stale User Accounts
      • License
      • Test Page
    • Enzoic Web Product Console
      • Overview
      • Alerts
      • Activity History
      • Error Log
      • Server Status
      • Clients
      • Password Test
    • Logging and SIEM Integration
      • Generic SIEM Integration
      • CrowdStrike Falcon Integration
    • Backup Considerations
    • Troubleshooting
  • Release History & Notes
Powered by GitBook
On this page

Was this helpful?

  1. Product Usage
  2. Logging and SIEM Integration

CrowdStrike Falcon Integration

Enzoic for Active Directory v3.6

PreviousGeneric SIEM IntegrationNextBackup Considerations

Last updated 5 days ago

Was this helpful?

Enzoic for Active Directory audit events can be pushed directly to your Crowdstrike Falcon instance. This allows you to leverage the rich search capabilities built into Falcon.

2.1 Falcon Configuration

  1. From the hamburger menu at the top left, click Next-Gen SIEM, then in the flyout, click Data onboarding

  2. Click the Data sources tab.

  3. Click Search by name, and enter “http” (without quotes).

  4. Click on the HEC / HTTP Event data source.

  5. Enter the required information to setup the data source as follows

    1. For Data source, enter enzoic-for-ad-audit-log-data-source

    2. Select JSON as the Data type

    3. For Connector name, enter enzoic-for-ad-audit-log-connector

    4. In the Parsers drop down, search for and select the enzoic-enzoicforactivedirectory parser.

    5. Tick the affirmation checkbox at the bottom, above the Cancel button.

    6. Click Save

  6. Click Close on the modal popup.

  7. Towards the top right of the page, click the Generate API Key button.

  8. On the Connection setup modal popup, copy off the API key and API URL values to a save and secure location. You will also need these to configure Enzoic for Active Directory in the next steps.

  9. In the Enzoic for Active Directory console, click Settings in the left navigation panel, then click on the Crowdstrike tab page.

    1. Enter the API URL and API Key generated by Falcon, tick the Enabled checkbox, then click Update Configuration.

Enzoic for Active Directory is now setup to push all audit events to your Falcon instance.